Who we are
RebridPro is built and operated by Rebrid One, LDA, a company registered in Portugal (NIPC/VAT PT519352122) with its registered office at Avenida Manuel Violas 476, 4410-137 São Félix da Marinha, Vila Nova de Gaia, Portugal. This policy covers the website at https://www.rebridpro.com and the RebridPro application. Questions about it go to admin@rebridpro.com.
RebridPro is an operations platform: it helps operators run what happens after a booking exists - staffing, scheduling, resources, customer communication and reporting. It is not a booking or selling platform and it does not take payments from an operator's customers.
Controller or processor
Two different relationships apply, depending on whose data it is.
Rebrid as controller
For your own account (name, email, password, sign-in method, subscription), for website visits and for security logs, Rebrid One LDA decides why and how the data is used. We are the controller.
Rebrid as processor
For the customer, staff and booking records an operator enters into RebridPro or imports from a connected system, the operator decides why that data exists and what happens to it. The operator is the controller and Rebrid processes it on their instructions only. If you are a customer of an operator that uses RebridPro, contact that operator first with any request about your data - they hold it, and we act on what they tell us. Section 11 sets out the terms that apply to operators.
Data we collect
Account and profile
- Name, email address, optional phone number and company name, and a profile photo if you add one.
- A hashed password if you sign up with email, or the identity returned by Google, LinkedIn or Facebook if you use social sign-in. Social sign-in runs through Supabase Auth; we receive your name, email and provider id, not your password or your contacts.
- Your user type, the organizations you belong to, your role and permissions in each, and invitations sent to you.
Organization and billing
- Organization name, addresses, branches, time zone and settings.
- Subscription tier and status, and the Stripe customer and subscription ids. Card details are entered on Stripe's hosted checkout page and held by Stripe; we never see or store them.
Operational data entered by operators
Held on behalf of the operator (see section 2):
- Customers: name, email, phone, language preference, notes, allergy and dietary notes, accessibility needs, emergency contact, customer details including age or a child flag where the operator records them, answers to booking questions, and electronically signed waivers.
- Staff: name, contact details, role, certifications, languages, availability, shifts, time entries and clock in/out records, assigned jobs and tasks.
- Bookings, products, resources, vehicles, maintenance, documents, invoices and internal communication logs.
- Bokun, when connected: the API access and secret keys the operator supplies, stored in the database and used only to import that operator's bookings, products and customers.
Usage and technical data
- First-party analytics, only after you accept cookies: a random visitor id, a per-tab session id, pages viewed, in-app events (for example a form submitted or an error shown), device type and browser derived from your user agent, and country and city derived from your connection. We do not store your IP address in analytics.
- Google Analytics, only after you accept cookies (see section 12).
- Security events: failed and successful sign-ins, lockouts, password and account changes, with the IP address, user agent and email involved. These are kept whether or not you accept cookies, because they protect your account.
- Audit logs inside an organization: who did what, when, to which record, and from which IP - visible to the organization's administrators.
- Support, feedback and contact form messages you send us, and the emails we send you (delivery status only).
Data stored on your device
If you use offline mode, a copy of your own assigned jobs and any actions you take while offline are stored in your browser (IndexedDB) until they sync. Cookies and local storage are listed in the Cookie Policy.
Why we use it and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service you signed up for | Account, organization, operational data | Contract (Art. 6(1)(b)) |
| Billing the operator's subscription | Billing data, Stripe ids | Contract; legal obligation for invoices |
| Sending transactional email - sign-in codes, invitations, reminders, notifications | Email address, name | Contract |
| Keeping accounts secure - lockouts, IP blocking, bot checks | Security events, IP address | Legitimate interest in preventing abuse |
| Understanding how the product is used | Analytics data | Consent (cookie banner) |
| Answering support and contact requests | Your message and contact details | Legitimate interest; contract |
| Complying with law, responding to lawful requests | Whatever is required | Legal obligation |
Emails an operator sends to their customers through RebridPro (booking reminders, waiver links, post-activity thank-you messages) are sent on the operator's instruction. Post-activity and marketing-style messages carry an unsubscribe link that sets an opt-out flag on that customer's record, after which RebridPro will not send them further messages of that kind.
Who we share it with
We share personal data only with the vendors below, each under a contract that restricts how they may use it. We never sell it.
| Vendor | What they do for us | Location |
|---|---|---|
| Supabase | Database and authentication (including social sign-in) | EU - Ireland (eu-west-1) |
| Amazon Web Services | File storage (S3) and transactional email (SES) | EU - Stockholm (eu-north-1) for S3 |
| Vercel | Hosting and serving the website and application | Global edge network; may process outside the EU |
| Stripe | Subscription billing and hosted checkout | EU and US |
| Google (Analytics) | Website analytics - only after consent | May process outside the EU |
| Cloudflare (Turnstile) | Bot check on the registration form | May process outside the EU |
| Open-Meteo | Weather forecasts for activity locations - receives only coordinates or a city name, never personal data | EU |
| Bokun (only when an operator connects it) | Source of imported bookings, products and customers | Depends on the operator's Bokun account |
Links to Google Maps in the app are plain links; nothing is sent to Google until you open one. We will update this list before adding a new vendor that handles personal data.
Where data is stored
The database and authentication system run in Supabase's EU region in Ireland. Uploaded files (documents, photos, waivers) sit in a private AWS S3 bucket in Stockholm, encrypted at rest and blocked from public access. Backups an operator downloads are generated on request, not stored by us.
Vercel, Google, Stripe and Cloudflare may process limited data outside the European Economic Area. Where they do, transfers rely on the European Commission's standard contractual clauses or an adequacy decision, as set out in each vendor's data processing terms.
How long we keep it
- Your account - for as long as it exists. When you delete it, your name, email, phone, company name, photo, certifications, notifications and personal events are removed or replaced with placeholder values immediately. A bare, anonymised record stays so that history inside organizations you worked in (who ran a booking, who approved a task) still adds up.
- Organization data - for as long as the organization exists. Deleting an organization removes its data and cancels its subscription immediately.
- Customer and communication data inside an organization - as set by that operator's data retention rules (Security → Data retention): inactive customers can be anonymised and old communication logs deleted after a period the operator chooses. By default nothing is removed automatically.
- Security events and audit logs (sign-in attempts, account lockouts, admin actions) - kept 90 days, then deleted automatically.
- First-party analytics (site visits, page views, in-product events) - kept 14 months, then deleted automatically.
- Invoices and billing records - for the period Portuguese tax law requires, currently ten years.
- Offline data on your device - until it syncs, or until you sign out or clear site data.
Security
- Passwords are hashed with a slow, salted algorithm and are never stored or logged in plain text. One-time codes are hashed too.
- Sessions use HTTP-only, secure cookies. Access tokens expire after one hour and refresh tokens after 30 days.
- Repeated failed sign-ins lock the account temporarily and block the source IP; a bot check runs on registration.
- Data is encrypted in transit (TLS) and at rest in both the database and file storage.
- Access inside an organization is limited by role and permission; every change is written to the audit log.
- If we become aware of a breach that puts your data at risk we will notify the affected operators without undue delay, and the supervisory authority within 72 hours where the GDPR requires it.
Your rights
Under the GDPR you can ask us to:
- Access the personal data we hold about you and get a copy.
- Correct anything inaccurate - most of it you can edit yourself under Account settings.
- Delete your data (see section 10).
- Export it in a portable format. Operators can download a full backup of their organization at any time from Security → Backup.
- Object to processing based on our legitimate interests, or restrict it while a dispute is resolved.
- Withdraw consent for analytics at any time through the cookie settings on the Cookie Policy page.
Email admin@rebridpro.com from the address on your account. We answer within one month. If your data was entered by an operator, we will pass your request to them or ask you to contact them directly, since they are the controller.
How to delete your data
Delete your own account
- Sign in and open Account settings.
- Scroll to the Danger zone and choose Delete account.
- Enter your password to confirm. The deletion takes effect immediately and signs you out everywhere.
If you own an organization you must first transfer ownership to another member or delete the organization (Organization settings → Danger zone, typing its exact name to confirm). Deleting an organization cancels its subscription immediately and removes its data.
If you signed up with Google, LinkedIn or Facebook, deleting your account removes the link to that provider as well. Removing RebridPro from your provider's connected-apps page does not delete your RebridPro account - use the steps above, or email us.
If you cannot sign in
Email admin@rebridpro.com from the address on the account with the subject "Delete my account". We will verify it is you and delete it within 30 days.
If you are a customer of an operator
Ask the operator. They can delete or anonymise your record from their customer list. If you cannot reach them, email us with the operator's name and we will help.
For operators: processing terms
These terms apply between Rebrid One LDA (processor) and any operator (controller) that stores personal data in RebridPro, and form part of the Terms of Use.
- We process customer and staff data only to provide the service and only on your documented instructions, which include the settings you configure and the actions you and your members take in the product.
- We use the sub-processors listed in section 5 and will update that list before adding one. You may object within 30 days of an update; if we cannot resolve the objection you may terminate the affected organization.
- We keep the security measures in section 8, limit staff access to what support requires, and bind everyone who accesses data to confidentiality.
- We help you respond to data subject requests with the tools in the product (customer records can be edited, exported, anonymised or deleted) and, where those are not enough, by email.
- We tell you without undue delay about any personal data breach affecting your data.
- When you delete your organization, we delete its data. You can download a full backup beforehand.
- You confirm you have a lawful basis to collect the data you enter - including a customer's consent where you record health-related notes such as allergies or accessibility needs - and that you provide your own privacy notice to your customers.
Analytics and SEO tooling
We use two Google tools. Google Analytics runs on this site only after you choose "Accept all" in the cookie banner; before that, or after "Reject non-essential", its script is never loaded. Google Search Console reads only our public pages to report how they appear in search; it receives no visitor data from us. We do not use advertising pixels or retargeting.
Children
RebridPro is a business tool for adults acting on behalf of a business. You must be at least 18 to create an account. Operators may record details of minors who take part in their activities (for example a customer's age or a child flag); they do so as controller and are responsible for having the right to collect it.
Changes to this policy
We will update this page when our practices change and update the date at the top. For material changes we will email account holders before the change takes effect.
Contact and complaints
Data requests and questions: admin@rebridpro.com.
If you think we have handled your data unlawfully you can complain to Portugal's data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at cnpd.pt, or to the supervisory authority in the EU country where you live or work.